Apply Edge Start your job search

Senior DevSecOps Engineer

AGAPI · Dubai, United Arab Emirates

Apply & track with Apply Edge

Job Summary: This is a hands-on engineering role focused on building the shared automation backbone for security operations and the software development lifecycle.You’ll help eliminate operational toil, automate security workflows, and embed security into modern DevOps practices through scalable, reliable DevSecOps tooling and platforms.

Responsibilities

Build and maintain CI/CD security automation across GitHub, GitLab, Jenkins, or Azure DevOps.Integrate SAST, DAST, SCA and security testing tools such as Semgrep, ZAP, Nuclei and Burp.Process and normalize security findings in SARIF/JSON and route results into platforms such as DefectDojo and Jira.Implement security checks for Terraform, CloudFormation, Dockerfiles, container images and cloud infrastructure.Develop security telemetry ingestion, enrichment, schema mapping and quality controls for AWS, Azure, Windows and M365 sources.Build and maintain reusable security artefacts, rules, templates and notebooks for red, blue and purple team activities.Create disposable Active Directory, cloud and containerized lab environments using Terraform and Ansible.Develop automation and self-healing capabilities to improve pipeline reliability and security operations.Establish security metrics, SLIs/SLOs and build-stage security gates to provide engineering visibility.Identify manual inefficiencies and continuously improve security workflows and practitioner experience.Work closely with software engineering teams and security operations to turn requirements into intuitive, scalable tooling.

Job Requirements

Years of experience:Minimum 6yrs ProgrammingAdvanced proficiency in Python or Go.Strong experience building automation, APIs and internal tooling.CI/CD & DevOpsHands-on experience with Jenkins, GitHub Actions, GitLab CI or Azure DevOps.Familiarity with GitOps principles and modern DevOps practices.Security EngineeringPractical experience with ZAP, Semgrep, Nuclei, SARIF, JSON, CycloneDX and SBOMs.Understanding of vulnerability management and security testing automation.Cloud & ContainersExperience with Docker and Kubernetes.Practical experience with AWS and/or Azure.Understanding of container image hardening and runtime security controls.Data & TelemetryExperience with log parsing, schema mapping, enrichment and streaming technologies such as Kafka, Kinesis or equivalent.Infrastructure as CodeExperience with Terraform, CloudFormation, Ansible or similar technologies.CollaborationProven ability to work across both software engineering and security operations teams.Strong ability to translate technical security requirements into practical, developer-friendly solutions.Nice to Have:Experience implementing OWASP DSOMM.GIAC Cloud Security Automation (GCSA).HashiCorp Certified: Terraform Associate.Certified Kubernetes Administrator (CKA).DevSecOps/DevOps certifications such as DSOE or CDP.